English

Principal ideal problem and ideal shortest vector over rational primes in power-of-two cyclotomic fields

Cryptography and Security 2026-01-16 v2

Abstract

The shortest vector problem (SVP) over ideal lattices is closely related to the Ring-LWE problem, which is widely used to build post-quantum cryptosystems. Power-of-two cyclotomic fields are frequently adopted to instantiate Ring-LWE. Pan et al. (EUROCRYPT~2021) explored the SVP over ideal lattices via the decomposition fields and, in particular determined the length of the shortest vector in prime ideals lying over rational primes p3,5(mod8)p\equiv3,5\pmod{8} in power-of-two cyclotomic fields via explicit construction of reduced lattice bases. In this work, we first provide a new method (different from analyzing lattice bases) to analyze the length of the shortest vector in prime ideals in Z[ζ2n+1]\mathbb{Z}[\zeta_{2^{n+1}}] when p3,5(mod8)p\equiv3,5\pmod{8}. Then we precisely characterize the length of the shortest vector in the cases of p7,9(mod16)p\equiv7,9\pmod{16}. Furthermore, we derive a new upper bound 22n+1p4\sqrt[4]{2^{2n+1}p} for this length, which is tighter than the bound 2np42^n\sqrt[4]{p} obtained from Minkowski's theorem. Our key technique is to investigate whether a generator of a principal ideal can achieve the shortest length after embedding as a vector. If this holds for the ideal, finding the shortest vector in this ideal can be reduced to finding its shortest generator.

Keywords

Cite

@article{arxiv.2601.07511,
  title  = {Principal ideal problem and ideal shortest vector over rational primes in power-of-two cyclotomic fields},
  author = {Gaohao Cui and Jianing Li and Jincheng Zhuang},
  journal= {arXiv preprint arXiv:2601.07511},
  year   = {2026}
}

Comments

22 pages